New · The guide “Mastering Claude at work”, free. Download it →

Last reviewed:

What is the AI Act? Definition and business implications

The AI Act is European Regulation 2024/1689, the world's first legal framework to classify AI systems by risk level and to impose differentiated obligations: prohibition for unacceptable uses, strict requirements for high-risk systems, transparency for the rest.

The AI Act (EU Regulation 2024/1689) entered into force on 1 August 2024, with a progressive application until 2027. The text classifies AI systems into four risk levels. Unacceptable risk (banned since February 2025): social scoring, behavioural manipulation, real-time biometric identification in public spaces. High risk (applicable from 2 August 2026): AI systems in recruitment, education, justice, credit, insurance, public services. These systems require detailed documentation, testing, European registration, human oversight. Limited risk: transparency obligations (informing the user that they are interacting with AI). Minimal risk: no specific obligation. Foundation model (GPAI) providers have their own obligations since August 2025: documentation of training sources, copyright compliance policies, evaluation of systemic risks for powerful models.

Concrete example

A 800-employee French mid-cap uses an AI tool to filter candidate CVs for hiring. Under the AI Act, this system falls into the “high risk” category (annex III, point 4 of the regulation). From 2 August 2026, the company (or its provider, depending on the responsibility split) must have detailed technical documentation of the system, a conformity assessment, an effective human oversight mechanism, and a registration declaration in the European database. Non-compliance exposes to sanctions of up to 35 million euros or 7% of worldwide turnover, whichever is higher.

A second case, more frequent than one might think: a customer-service chatbot. A French insurance company deployed a GPT-powered chatbot in 2025 to answer recurring questions from policyholders (claims filing, pricing, products). The chatbot is not classified as "high risk" — but it falls into the AI Act's "limited risk" category (article 50): a transparency obligation, users must be clearly informed they are interacting with an AI. Adding a banner such as "Virtual assistant — you are chatting with an AI" plus on-demand access to a human operator is enough to comply. Cost: a few dev hours + one sentence of communications policy. This is the most common case in 2026, and the most often overlooked.

Comparison

The 4 AI Act risk categories and their obligations
CategoryTypical examplesMain obligationsEntry into force / max penalty
Unacceptable riskSocial scoring, subliminal manipulation, emotion recognition at work or school, real-time biometrics in public spaces (with narrow exceptions)Complete ban on placing on the market or use in the EUSince 2 February 2025 — up to €35M or 7 % of global turnover
High riskCV filtering, credit scoring, biometric control, medical devices, critical infrastructure, education, justiceRisk management system, quality data, technical documentation, human oversight, robustness, transparency, EU database registration2 August 2026 (Annex III) or 2 August 2027 (already-regulated products) — up to €15M or 3 % of global turnover
Limited risk (transparency)Chatbots, deepfakes, biometric categorisation systems, AI-generated contentClearly inform users they are interacting with an AI or that content is AI-generated (article 50)2 August 2026 — up to €15M or 3 % of global turnover
Minimal riskSpam filters, AI in video games, basic recommendation engines (the vast majority of systems)No specific obligations — voluntary codes of conduct encouragedNo entry-into-force obligation — no specific penalty

FAQ

When does the AI Act take effect?

Legal entry into force on 1 August 2024, phased application. Bans (unacceptable risk) apply since 2 February 2025. Obligations for foundation models (GPAI) apply since 2 August 2025. The bulk of the text, including high-risk systems, applies from 2 August 2026. High-risk systems built into already-regulated products (medical devices, toys…) have until 2 August 2027.

What penalties does the AI Act impose?

Three tiers, each expressed as the higher of a fixed sum or a percentage of global turnover: €35M or 7 % for use of banned systems, €15M or 3 % for breaches of high-risk or GPAI obligations, €7.5M or 1 % for supplying inaccurate information to authorities. SMEs and start-ups benefit from proportionally reduced caps.

Am I affected by the AI Act if my AI vendor is American or Chinese?

Yes. The AI Act applies as soon as an AI system is placed on the market or used in the EU, regardless of the vendor's country. As an EU-based "deployer", you are responsible for the obligations that fall on you (transparency, human oversight, informing people) even if the AI comes from OpenAI, Google or Alibaba. Your contracts should provide for the necessary safeguards.

What's the difference between the AI Act and GDPR?

GDPR governs the processing of personal data (purpose, legal basis, informing subjects). The AI Act governs AI systems themselves (risk classification, design obligations, transparency about AI). The two apply in parallel: an AI system processing personal data must comply with both. In practice they complement each other — GDPR alone never covered the specific risks of generative AI.

How do I know if my AI use case is "high risk"?

Annex III of the AI Act lists high-risk uses: biometrics, critical infrastructure, education, employment and HR (including CV screening, employee rating), access to essential services (credit, insurance, welfare), law enforcement, migration and asylum, justice, democratic processes. If your use case falls in one of these categories — or if your AI system is a safety component of an already-regulated product — you are in high risk.

Does the AI Act ban some AI uses outright?

Yes, eight practices are banned (article 5): social scoring by public authorities, subliminal manipulation, exploitation of vulnerabilities of individuals, emotion recognition in the workplace or in schools, biometric categorisation on sensitive traits (origin, orientation), untargeted scraping of faces from the internet or CCTV, predicting offences solely from profiling, real-time biometrics in public spaces (with narrow law-enforcement exceptions).

See also

Further reading

Regulation (EU) 2024/1689 on artificial intelligence, EUR-Lex (external resource)

Sources

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (AI Act). https://eur-lex.europa.eu/eli/reg/2024/1689/oj (accessed 2026-05-24)
  2. AI Act, European Commission, official presentation page. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai (accessed 2026-05-24)

← Back to glossary

Address copied